CVE-2020-28487

Summary: 
This affects the package vis-timeline before 7.4.4. An attacker with the ability to control the items of a Timeline element can inject additional script code into the generated application.
Published: 
Friday, January 22, 2021 - 18:15
cvss: 
5.0